Privacy
Your data, in plain words.
If you tell us a story you're handing us something private. This page says what we do with it, who reads it, how long we keep it and how we give it back to you. It's written to actually be read, not to be accepted in a hurry.
Who handles your data
Rocco Savatta — Gela (CL) · Italian VAT no. 01941470856
Midnight Stories is a project by Jumper Studio.
For anything at all, just reply to the email you get when you send a story.
What we collect
- Your story, exactly as you wrote it.
- Name and email, because without them we can't reply to you.
- Your phone number, only if you write it in. It's not required.
- The dedication and the musical style you choose, if you fill them in.
- The language you read the site in and wrote your story in.
- The permissions you give us, one by one, with the exact text you read — in your language — and the day you read it.
- A fingerprint of your network address and the area you're coming from, roughly. They're only there to stop an automated program from filling the archive with fake stories. The fingerprint is encrypted in a way that can't be reversed: you can't get back to the address from it.
We don't ask for anything else, and in particular we never ask for payment details: nothing is paid from this site.
Why
- To read your story and reply to you — even if it isn't chosen.
- To make the month's selection, which a person decides by reading, not a program.
- To produce the song, if yours is the chosen story or if you ask us for a package.
- To publish, but only what you've allowed us to, item by item.
- To defend ourselves, if one day someone disputed what had been allowed: that's why we save the text of the permissions as it was that day.
On what basis
On your consent, which you give by ticking the boxes in the form. The boxes are kept separate on purpose: you can say yes to one and no to the others, and no publication consent is needed to take part. You can be chosen and stay invisible.
If instead you write to us about a package, we handle your data to reply to you and for any arrangements we may make: that's what's needed before a contract.
What exactly you've allowed
In the form you choose one single thing, and everything else follows from it:
- The song stays mine — We write it and we give it to you. It doesn't come out anywhere, and nobody tells your story.
- It can come out, but without my name — The song and the story can be published, but nobody will know they're yours.
- All of it can come out — Song, story and name. If yours is chosen, we tell it as yours.
Then there's an optional box, which you can leave empty without anything changing for the selection:
- You can keep my story in your archive and, one day, take inspiration from its theme to write something new. With this box your story stays in the archive and can be picked up again in later months. Without it, you still take part in this month's selection. The inspiration is about the theme or the feeling, not your story: no names, no places, no detail that could identify you.
When you send the story you get an email with your story and the exact list of the permissions you gave. That way you have a copy too, and you don't have to trust our memory.
Who reads it
A person on the editorial team. The stories sit in a password-protected archive, and the site's bot doesn't read them: it answers questions written by us and has no access to any story.
The alert that tells us a story has arrived goes through an outside service (WhatsApp), and for that reason it doesn't contain a single word of what you wrote: it only says there's something to read in the panel. None of your personal data crosses that channel.
The editorial team works in Italian. If your story arrives in another language, it's read as it is: the text isn't sent to any outside service to be translated.
Who we give it to
We don't sell anything to anyone and we don't run ads with your data. We rely on:
- Netlify, which hosts the site and the archive.
- Resend, which sends the emails.
- CallMeBot, for the WhatsApp alert — which, as said above, contains no data of yours.
Some of these providers may handle data outside the European Union, with the safeguards European rules require.
How long we keep it
There's no fixed deadline, and we say so openly instead of writing down a number we wouldn't stick to. There's no program deleting stories overnight either: how long we keep them is decided by these criteria, not by a clock.
- If you haven't given us permission to keep it, we keep it for as long as the month's selection and the reply take.
- If you have, it stays in the archive as long as the project needs it — that is, as long as it can be pulled out again for a song or for the story archive.
- If you ask us to delete it, we delete it.
- Anything to do with invoices and payments we keep for as long as tax law requires.
How you change your mind
Reply to the email you received, or write to us. You can ask to see what we have, to correct it, to delete it, to limit its use, to take it elsewhere, and you can withdraw a permission you had given.
When you withdraw your consent we switch everything off: we stop using the song, the story, and the theme as a starting point for anything else. If you ask us to delete, we delete.
One thing it's right that you know, because nobody ever writes it down. To take on a request like that — work out which story it is, switch the permissions off, delete it and be able to show that we did — whoever handles it has to be able to open that record. It's the only way to do what you ask and to leave a trace of it, and that's what we do. We don't do it to keep the story alive: we do it to close it properly.
If you think we're getting it wrong, you can go to the Italian data protection authority, the Garante per la protezione dei dati personali (garanteprivacy.it). If you live in another European Union country you can go to the supervisory authority in your own country.
Under-eighteens
To send a story you have to be at least eighteen, and there's a box that says so. If we find out that a story comes from someone under eighteen, we delete it.
Automated decisions
There aren't any. The story of the month is chosen by a person reading. There's no score, no ranking and no program deciding in their place.
Cookies
This site doesn't use profiling cookies and has no advertising trackers. The browser stores three things only, and all three are there to make the site work:
- The language you chose, if you switch it by hand, so that on your next visit you don't find yourself in another language. It lasts a year and you can delete it from your browser settings.
- The bot's voice turned on, if you turn it on — and only for the length of this visit.
- The bot's bubble closed, if you close it, so it doesn't pop up again for the rest of your visit. It goes away when you close the tab.
In the editorial panel there's a technical cookie that keeps the session open for whoever logs in with the password. That's about us, not about people visiting the site.
How we count visits
We count how many pages get opened, because otherwise we'd have no idea whether anyone is seeing this project. We do the counting ourselves: no Google Analytics, no external services, no third-party scripts. What this site counts never leaves this site.
- No cookie. The counting writes nothing into your browser and asks you nothing.
- Your IP address is never stored. Your address, your browser and today's date make a fingerprint that changes every night. It's there so you're not counted five times if you open five pages tonight; tomorrow it's a different one, and it can't identify you.
- No link to your story. Visits and stories live in two separate archives, and there is no key that joins them. Knowing that someone opened the form today doesn't say who, and there's no way back from a number to a person.
What stays, for each day, are totals: how many pages opened, how many people, which pages, where they came from and which language they were reading in. The individual steps aren't kept.
If this page doesn't answer a question of yours, write to us: we'll rewrite it.